Skip to content

Simpson Senior Services

Disclosed Dec 31, 20205 years ago3,259 affectedConfirmed

Official notice

Simpson Senior Services, the covered entity (CE), reported that multiple employees were the subjects of an email phishing scheme that compromised the protected health information (PHI) of 3,529 individuals. The PHI involved included names, addresses, dates of birth, lab results, medications, diagnoses, and additional treatment information. The CE notified HHS, affected individuals, the media, and posted substitute notice on its website. In its mitigation efforts, the CE implemented additional administrative, technical, and security safeguards to better protect its sensitive data. All staff were retrained.

What is known

People affected3,259 (as reported to HHS)
DisclosedDec 31, 2020
HappenedNov 24, 2020
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INDec 31, 20202
HHS archivetotalDec 31, 20203,259
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 2474 to 3259 · backfill source
  • 2026-09-25 · summary: empty to Simpson Senior Services, the covered entity (CE), reported that multiple employees were the subjects of an email phishing scheme that compromised the protected health information (PHI) of 3,529 individuals. The PHI involved included names, · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Simpson Senior Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.